docs(migration): record the two Bedrock IAM users + scoped invoke policy (#74)
Some checks are pending
CI / Lint (push) Waiting to run
CI / Format check (push) Waiting to run
CI / Unit tests (push) Waiting to run
CI / Playwright E2E (push) Waiting to run

Document the live execution of MIGRATION.md §10.1 (Bedrock auth via static
keys): the customer-managed least-privilege policy open-swe-bedrock-invoke
and the open-swe-dev-bedrock / open-swe-prod-bedrock IAM users. Captures the
static-key deviation rationale (managed LangGraph Cloud cannot assume a role)
and that both mandatory gates (GPT-4.1 IAM cross-review, /sh-security-review)
passed with no critical/high.
This commit is contained in:
Adam Moussa 2026-06-30 14:38:47 -04:00 • committed by GitHub
parent 49fd48d32f
commit 8441bbb2d8
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -177,6 +177,18 @@ Post-#62 `SUPPORTED_MODELS` = `bedrock_converse:us.anthropic.claude-opus-4-8` (*
- (a) Static `AWS_ACCESS_KEY_ID` / `AWS_SECRET_ACCESS_KEY` / `AWS_REGION` for a **Bedrock-scoped IAM user** in the deployment env, or - (a) Static `AWS_ACCESS_KEY_ID` / `AWS_SECRET_ACCESS_KEY` / `AWS_REGION` for a **Bedrock-scoped IAM user** in the deployment env, or
- (b) Run the agent on **Fireworks** and avoid Bedrock entirely on managed. - (b) Run the agent on **Fireworks** and avoid Bedrock entirely on managed.
### Bedrock IAM users (CREATED — resolves §10.1, discharges the §9 IAM gates)
Option (a) was chosen and executed live (2026-06-30, account **328440206208** / **us-east-1**). This is **click-ops IAM** — there is no remaining open-swe AWS IaC after the decommission (#64), so these are created with the CLI, not CDK.
- **Customer-managed policy `open-swe-bedrock-invoke`** (`arn:aws:iam::328440206208:policy/open-swe-bedrock-invoke`). Least-privilege: actions `bedrock:InvokeModel` + `bedrock:InvokeModelWithResponseStream` **only**, scoped to exactly the `us.anthropic.claude-opus-4-8` inference-profile ARN + its **three** routed foundation-model ARNs (us-east-1, us-east-2, us-west-2). **No wildcards, no other models.** (Supersedes the §10.1 plan to reuse the #62 instance-role policy — a fresh standalone policy was minted instead.)
- **Two IAM users**, each attached to that policy: **`open-swe-dev-bedrock`** and **`open-swe-prod-bedrock`**. Tagged `project=open-swe`, `managed-by=cli-migration`, `purpose=bedrock-invoke`.
- **Static access keys are minted separately by the owner** (`aws iam create-access-key`) — secret keys live **only** in the deployment env stores, never in this repo or memory. dev key → dev env; prod key → LangGraph Cloud prod config (`AWS_ACCESS_KEY_ID` / `AWS_SECRET_ACCESS_KEY` / `AWS_REGION=us-east-1`).
- **Deviation rationale:** static long-lived keys are a deliberate departure from the Sea Haven OIDC norm because **managed LangGraph Cloud cannot assume an AWS role**. Mitigated by the tight least-privilege policy above.
- ✅ **Both mandatory gates ran and PASSED:**
- **GPT-4.1 IAM cross-review** (confirmed hit `gpt-4.1-2025-04-14`) — least-privilege confirmed.
- **`/sh-security-review`** — **0 critical/high**; two **accepted mediums** (the static-key deviation + no per-principal budget cap).
- **Recommended follow-ups:** shortest viable key-rotation cadence with recorded creation dates; an AWS Budgets / CloudWatch anomaly alarm on per-principal Bedrock `InvokeModel` volume; confirm CloudTrail captures these users.
--- ---
## 5. Required Code Fixes (the 6 gotchas) ## 5. Required Code Fixes (the 6 gotchas)